[ 
https://issues.apache.org/jira/browse/GEODE-10592?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099828#comment-18099828
 ] 

ASF subversion and git services commented on GEODE-10592:
---------------------------------------------------------

Commit 978012290cb09e90c1d2adbb00801adc440965d3 in geode's branch 
refs/heads/develop from Jinwoo Hwang
[ https://gitbox.apache.org/repos/asf?p=geode.git;h=978012290c ]

[GEODE-10592] Remediation of CVE-2026-40984 (#8018)

* Remediation of CVE-2026-40984

* CI build failure

* Update CodeQL and actions to specific versions (v4.2.2/v4.7.1) to resolve 
Node.js 24 warnings

> Remediation of CVE-2026-40984
> -----------------------------
>
>                 Key: GEODE-10592
>                 URL: https://issues.apache.org/jira/browse/GEODE-10592
>             Project: Geode
>          Issue Type: Improvement
>            Reporter: Jinwoo Hwang
>            Assignee: Jinwoo Hwang
>            Priority: Major
>
> Affected versions of this package are vulnerable to Allocation of Resources 
> Without Limits or Throttling via HTTP server metrics instrumentation in 
> Micrometer. An attacker can cause denial of service by sending specially 
> crafted HTTP requests that trigger excessive resource consumption during 
> metrics collection and processing. Repeated requests can degrade application 
> performance and potentially render the service unavailable.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to